Elastic Security Labs identified the operation, tracked as REF9334, after observing over 1,500 infected systems, 98.75% of which are located in Brazil. The malware targets financial credentials by installing unauthorized browser extensions in Chrome and Edge. It achieves this by manipulating Secure Preferences and regenerating integrity hashes, a technique that bypasses standard installation approval processes. The campaign impersonates major Brazilian financial institutions, including Banco do Brasil, Santander, and Mercado Pago, to distribute loaders disguised as invoices or receipts.
The use of blockchain technology marks a significant shift in the malware's modularity. Since May 2026, the operators have utilized Ethereum smart contracts to store configuration values. These contracts act as a dead-drop resolver, allowing infected machines to fetch the latest locations for malicious payloads. By simply updating the on-chain data, the attackers maintain persistence even as security teams block traditional servers. Elastic researchers gained visibility into the campaign by registering an unused domain that the malware used for anti-analysis checks, effectively turning the attackers' own sandbox-detection mechanism against them to halt further infection stages.
While the malware is dubbed KREMLIN, Elastic found no evidence of Russian state involvement, attributing the name to the author’s handle. Analysis of an Ethereum wallet linked to the infrastructure revealed 82 USDT transfers and activity patterns consistent with the UTC-3 time zone, suggesting a local origin for the operation. Although the current intervention has temporarily disrupted the campaign, the infected systems remain compromised, and the attackers continue to rotate their infrastructure via the blockchain.

Comments (0)
No comments yet. Be the first!